Vulnerability record · CVE-2020-12845 · published 27 July 2020
CVE-2020-12845: Cherokee-project cherokee null pointer dereference vulnerability
Cherokee Project · Cherokee
Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within cherokee_validator_parse_basic or cherokee_validator_parse_digest.
Description
Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within cherokee_validator_parse_basic or cherokee_validator_parse_digest.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://cherokee-project.com/downloads.html | Vendor Advisory |
| https://github.com/cherokee/webserver/issues/1242 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/cherokee/webserver/releases | Third Party Advisory |
| https://security.gentoo.org/glsa/202012-09 | Third Party Advisory |
| http://cherokee-project.com/downloads.html | Vendor Advisory |
| https://github.com/cherokee/webserver/issues/1242 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/cherokee/webserver/releases | Third Party Advisory |
| https://security.gentoo.org/glsa/202012-09 | Third Party Advisory |
Track CVE-2020-12845 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12845), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.